Part 10 · 1 chapters · ~8 min
tcpdump and Wireshark
Capturing packets safely, capture and display filters, reading a TCP conversation, following streams, spotting retransmissions, resets and zero windows, decrypting TLS in a lab with key logs, and analysing DNS and HTTP in captures.
20
Capture and read
code
# capture: filter at capture time to keep files small; -s 0 for full packets tcpdump -i any -nn -s 0 -w /tmp/api.pcap 'host 203.0.113.10 and port 443' tcpdump -i any -nn 'udp port 53' # watch DNS live tcpdump -i any -nn 'tcp[tcpflags] & (tcp-syn|tcp-rst) != 0' # connection attempts and resets # Wireshark display filters tcp.analysis.retransmission tcp.flags.reset == 1 tcp.analysis.zero_window dns.flags.rcode != 0 http.response.code >= 500 tls.handshake.type == 1 # lab only: decrypt TLS by having the client log its session keys SSLKEYLOGFILE=/tmp/keys.log curl https://localhost:8443/ # Wireshark → Preferences → TLS → (Pre)-Master-Secret log filename = /tmp/keys.log
| Wireshark feature | use |
|---|---|
| Follow TCP Stream | see one conversation as text |
| Statistics → Conversations | who talked to whom, how much |
| Expert Information | retransmits, resets, malformed packets, summarised |
| I/O graphs | throughput and retransmits over time |
| TCP stream graph (Stevens) | sequence numbers over time: stalls and window limits are visible |
Safety: captures can contain personal data and credentials; capture the minimum, store briefly, and never key-log production TLS.